Hackers could have taken over AWS
theregister.co.uk
theregister.co.uk
I wonder how many do care if it's the same account. Like people sleep well with their data on DropBox.
Those who care, think and create separate account.
Can we have a workflow or multi-level authorizations for critical actions like delete or terminate actions of cloud resources?.
I do think this story is noteworthy, not because of the headline, but because it draws attention to the underlying deficiencies of XML cryptography, as others have pointed out in comments.
I don't see how that's FUD. There was a problem, they found it, they let Amazon fix it, then they reported what they'd found.